Splunk SOAR

Phantom double Parameters when send email

bviehmann
New Member

hello I scan systems with nessus on vulnerbilities and send them to splunk.

With phantom I could generate emails. An event is a system for me and the vulnerbilities are the artifacts. When i send an email then some parameters will come up double .... how can i change that?

here an example:

Guten Tag Herr Tobias, Tobias

Betroffene Plattform
IP: 10.11.12.13, 10.11.12.13
Hostname: 244.abc.de, 244.abc.de

Sicherheitsrisiko: high, high

80/TCP, 443/TCP
blabla,

Lösungsvorschlag:
Unknown at this time., Unknown at this time

Tags (1)
0 Karma

cblumer_splunk
Splunk Employee
Splunk Employee

For your Use Case you will most likely want to use the Format Block's _as_list feature:
https://my.phantom.us/4.5/docs/automation/api_playbook#format

You Format Block template can look like this:
alt text

Use this DataPath to pass the full output of the Format Block to the 'body' parameter of the Send Email action block:
format_1:formatted_data

And your Email Body will look like this:
alt text

0 Karma

bviehmann
New Member

@rsantoso_splunk here is an example from my playbook alt text

0 Karma

rsantoso_splunk
Splunk Employee
Splunk Employee

@bviehmann, please check your artifact's event to see either of the following?
1. The Artifact deviceAddress contains two address 10.11.12.13, 10.11.12.13 Or
2. There are two Artifacts that contain the same address 10.11.12.13

0 Karma

rsantoso_splunk
Splunk Employee
Splunk Employee

Hi bviehmann,

I assume you use the format Template to fill in your email body?
How is the template and parameters look like?

Please check the format block documentation if you not already have:
https://my.phantom.us/4.1/docs/vpe/editor#format

0 Karma

bviehmann
New Member

Hi @rsantoso_splunk
yes i use the format Template .... in the documentation i dont find anythin about my problem ..(

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...